Compliance

EU AI Act Article 50: What Content Creators Actually Need to Do

Most coverage of the EU AI Act focuses on model developers and high-risk systems. Article 50 is different: its transparency duties attach to what an AI system does, not to how risky it is. Since August 2, 2026, it has bound the vendors who build generative tools and, for deep fakes and public-interest text, the agencies, freelancers, and brands who publish with them.

February 2026 · Updated September 202617 min readNumonic Team
Abstract visualization: Pink neon geometric network grid

The EU AI Act has generated thousands of articles about model safety, prohibited systems, and high-risk classification. Far fewer address Article 50—the provision that touches the agencies, freelancers, and brands producing AI content every day. It has applied since August 2, 2026. If you publish AI-generated images, copy, audio, or video in a professional capacity, this article is about you.

The EU AI Act (Regulation (EU) 2024/1689) is the EU's law on artificial intelligence. Article 50 is its transparency provision: the part that decides when AI-generated or AI-manipulated content must be disclosed, and by whom.

Disclaimer

This article is for informational purposes only and does not constitute legal advice. Numonic is not a law firm and does not provide legal counsel. Laws and regulations regarding AI-generated content vary by jurisdiction and are subject to change. You should conduct your own research and due diligence, and consult with qualified legal counsel in your jurisdiction before making compliance decisions.

Article 50 of the EU AI Act imposes transparency obligations on two kinds of actor: providers, who build AI systems and place them on the market, and deployers, who use them professionally. Unlike the high-risk provisions that dominate most coverage, Article 50 does not depend on risk classification. It covers chatbots and other interactive systems, synthetic image, audio, video, and text output, emotion recognition and biometric categorisation, deep fakes, and AI-generated text published to inform the public on matters of public interest.

This article is a translation exercise. We have read the Regulation, the European Commission's final Article 50 Guidelines of July 20, 2026, and the final Code of Practice on Transparency of AI-generated Content of June 10, 2026, and we have converted the obligations into steps that content creators, agencies, and in-house marketing teams can execute.

How to read this guide

We keep three layers apart throughout:

  • The law—what Article 50 of Regulation (EU) 2024/1689 says, as amended by Regulation (EU) 2026/1744. This is binding.
  • Commission guidance—how the Commission's July 2026 Guidelines and the Code of Practice interpret it. Market surveillance authorities can be expected to follow them, but they are not binding; only the Court of Justice of the EU can give an authoritative interpretation. Cited by paragraph number, e.g. “Guidelines, para. 117”.
  • Our recommendation—Numonic's practical advice. Marked as such. It is never a legal requirement.

Who Counts as a “Deployer”?

Article 3(4) of the EU AI Act defines a deployer as “any natural or legal person, public authority, agency or other body using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity.” This is deliberately broad, and the “personal non-professional activity” carve-out is narrower than most creators assume.

If you run a creative agency and generate images with Midjourney for a client campaign, you are a deployer. If you are a freelance designer using Stable Diffusion for paid client work, you are a deployer. If you are a brand's in-house marketing team using Adobe Firefly to produce social content, you are a deployer. If you are a solo creator using AI tools commercially—selling prints, licensing images, producing content for sponsors—you are a deployer.

The exemption covers genuinely personal use: generating art purely for yourself, with no professional or commercial dimension. The moment money or professional obligation enters the picture, the deployer definition applies.

Being a deployer does not require that you built or trained the AI system. Article 50 splits the work between the two roles: providers carry the design-time duties in Article 50(1) and 50(2); deployers carry the use-time duties in Article 50(3) and 50(4). The Commission reads “authority” over a system as the decision to deploy it and to decide how its outputs are used. It does not require technical control over the system (Guidelines, para. 12).

Does Article 50 Apply Outside the EU?

Often, yes. Providers are bound whether or not they are established in the EU (Guidelines, para. 10). Deployers established outside the EU are bound where they themselves foresee their AI output being disseminated and used in the Union—“including by posting deep fakes on the globally accessible internet”. They are not bound where content reaches EU audiences through channels that are unforeseeable and outside their control (Guidelines, para. 13). A UK or US agency running a campaign aimed at European audiences should assume Article 50 applies to it.

What Qualifies as an “AI System”?

Before any obligation attaches, there must be an AI system in the picture. Article 3(1) defines an AI system as “a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments.”

The critical word is infers. An AI system does not follow fixed, human-defined rules to produce output. It draws its own conclusions from input—a prompt, an image, a data set—and generates something new. Midjourney, Stable Diffusion, DALL·E, Adobe Firefly, Runway, and Sora all clearly meet this definition: they accept a prompt and infer images, video, or audio that did not exist before.

Software that merely stores, organises, converts, or distributes files—without itself performing inference—is not an AI system under Article 3. A traditional file manager, a cloud storage service, or a basic digital asset management (DAM) tool that catalogs files by filename and folder does not qualify.

Using AI Output vs. Deploying an AI System

A practical question the Act leaves open is what happens downstream. Consider a VFX studio that generates a set of AI backgrounds in Stable Diffusion and sells the rendered frames to a film production. The VFX studio is a deployer: it used the AI system. The film production never touched the AI tool—it bought finished image files—so on the text of Article 3(4) it is not itself a deployer of the image generator.

Two things follow from the Commission's guidance. First, AI backgrounds and effects produced as part of standard movie production are unlikely to make content “falsely appear to be authentic”, so they are often not deep fakes at all (Guidelines, para. 114). Second, where content is a deep fake, deployers in complex production and distribution chains “should take proportionate measures” to make sure their label actually reaches the audience, for example through contractual conditions with distribution partners (Guidelines, para. 12).

Our recommendation: if you create AI content professionally, treat yourself as its deployer and decide, per asset, whether it is a deep fake or public-interest text that needs a label. If you receive AI content from a supplier, you are not a deployer of the AI system, but you still have a commercial interest in the provenance metadata surviving the handoff: your own exposure under advertising standards, sector rules, and client contracts may require transparency about AI involvement.

Where Do AI-Native DAM Tools Fit?

Digital asset management platforms occupy an interesting position in the Article 50 framework. The answer depends on what the platform actually does.

A DAM that only stores, organises, tags (using fixed rules), and distributes files is not an AI system. It does not infer outputs from inputs—it follows deterministic logic. Traditional DAM platforms like basic folder-based systems, simple tagging databases, or file-sharing services fall outside Article 3 entirely.

An AI-native DAM is different. Platforms like Numonic use machine-learning models to auto-generate titles, descriptions, and tags from asset content—that is inference, and those specific features qualify as AI system components. Under the Act's framework, Numonic is a provider of those AI features (it develops and offers them) and its users are deployers when they invoke those features on their assets.

However, Numonic's core storage, organisation, search, and export functions that operate on user-supplied metadata and deterministic rules are not AI systems. The Act applies to the AI components, not to the entire platform.

What makes AI-native DAMs particularly relevant to Article 50 is not their own AI features but their role in the metadata supply chain. When a deployer generates an image in Midjourney, Article 50(2) is what requires the provider—Midjourney, not the deployer—to mark that output in a machine-readable format. But that marking is only useful if every tool in the post-creation workflow preserves it. A DAM that strips EXIF, XMP, or C2PA data on import or export breaks the transparency chain—even though the DAM itself has no Article 50 obligation as a non-AI tool, and even though the marking duty itself sits with the provider rather than with the deployer using the DAM.

This is why Numonic's privacy-aware export system (preserving IPTC 2025.1 fields and C2PA Content Credentials through configurable presets) exists: not because Numonic is legally required to preserve that metadata under Article 50, but because its users—the deployers—need the metadata to survive so they can meet their own transparency obligations. A DAM that silently strips provenance data makes compliance harder for everyone downstream.

Article 50, Paragraph by Paragraph

Article 50 contains four transparency obligations, each aimed at a different kind of AI system or output, plus a fifth paragraph that governs how and when the required information is given (Guidelines, section 2.1). Two of the four bind providers; two bind deployers. They can apply cumulatively: an image generator built into a chatbot may put 50(1) and 50(2) on its provider and 50(4) on whoever publishes a deep fake with it (Guidelines, para. 8). Each of paragraphs 1 to 4 also carries a narrow exception for systems authorised by law to detect, prevent, investigate, or prosecute criminal offences, which does not concern commercial content production.

Article 50(1): Telling People They Are Talking to AI (Provider Duty)

Providers of AI systems that interact directly with people, such as chatbots, voice assistants, and AI agents, must design them so that people are informed they are interacting with an AI system. The exception is where that is obvious to a person who is “reasonably well-informed, observant and circumspect”. The Commission says the exception should be read restrictively and judged against the system's foreseeable audience, which lowers the bar for what counts as obvious where children, older people, or people with disabilities are likely users (Guidelines, paras. 42–45).

For creative teams, this matters when you build rather than buy. An organisation that develops an interactive system in-house and puts it into service under its own name—a client-facing campaign chatbot, say—is its provider (Guidelines, para. 11).

Article 50(2): Machine-Readable Marking of AI-Generated Content (Provider Duty)

Article 50(2) requires providers of AI systems that generate synthetic audio, image, video, or text content to ensure the outputs are “marked in a machine-readable format and detectable as artificially generated or manipulated”, using technical solutions that are effective, interoperable, robust, and reliable as far as technically feasible. This is a duty on the tool vendor—the company building Midjourney, Stable Diffusion, or Adobe Firefly—not on the agency or creator using the tool. There is an exception for systems that perform an assistive function for standard editing or do not substantially alter the input data or its semantics.

The Commission's Guidelines also place some content outside 50(2) altogether (para. 68). Two exclusions matter to creators: short outputs such as single words, image captions, alt-text, and UI labels; and outputs used only in closed-loop production workflows for film, animation, games, or advertising. In a closed-loop workflow, only the final output has to be marked.

On timing, Regulation (EU) 2026/1744 gives providers of generative systems placed on the market before August 2, 2026 until December 2, 2026 to bring those systems into line with the marking obligation. The grace period covers 50(2) marking only, not Article 50 as a whole (Guidelines, para. 153).

The final Code of Practice sets out how providers can meet the obligation in practice. It takes a layered approach: digitally signed, tamper-evident metadata recording whether content is AI generated or manipulated (C2PA Content Credentials is the established standard of that kind), imperceptible watermarking, and, optionally, fingerprinting or logging.

Our recommendation for deployers: the marking obligation sits with the provider, but your delivery workflow decides whether that marking survives. Check which tools in your stack actually mark their output, and make sure your exports do not strip it. Many compression tools and social upload APIs remove metadata by default. When they do, the provider's marking never reaches the audience, and you lose the evidence you would want if a client or regulator asks how a given asset was made.

Multi-Layered Marking: What “Robust” Means in Practice

The statutory test is effectiveness, interoperability, robustness, and reliability, and the Code of Practice meets it with more than one layer. Our recommendation is to preserve every layer your tools produce, because each one fails in a different way:

  1. Embedded metadata (IPTC 2025.1 or XMP fields) that travels inside the file and is read by most DAM, CMS, and export tools. Easily stripped.
  2. Cryptographic provenance (C2PA Content Credentials) that binds a signed manifest to the file's content. Tamper-evident, but it can be lost on re-encoding.
  3. Invisible watermarking or fingerprinting that can survive re-encoding, screenshots, and format conversion. The fallback when metadata is gone.

Article 50(3): Emotion Recognition and Biometric Categorisation Disclosure (Deployer Duty)

Article 50(3) is a narrower, easy-to-miss deployer duty: deployers of an emotion-recognition system or a biometric categorisation system must inform the natural persons exposed to it that the system is in operation, and process their personal data in accordance with EU data-protection law. For content teams, this is most relevant to AI tools that infer a viewer's or subject's emotional state or biometric category—audience-reaction analytics, emotion-tagging of photos of people, or categorisation features bundled into a broader creative tool—rather than to image or video generation itself. It is separate from the marking and disclosure duties, and it carries a GDPR overlay that a generation-focused checklist can easily miss.

Article 50(4): Deep Fakes (Deployer Duty)

Article 50(4) requires human-perceivable disclosure—a visible or audible label that people understand without special tools. The Commission is explicit that deployers cannot rely on the provider's machine-readable 50(2) marking to discharge this duty, because those markings are not clear and distinguishable to the people exposed to the content (Guidelines, para. 117).

The duty only bites on content that is a deep fake. Article 3(60) defines one as AI-generated or manipulated image, audio, or video content “that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful”. The Guidelines apply four cumulative criteria—appreciable resemblance, to something that exists or plausibly could, being a person, object, place, entity, or event, which would falsely appear authentic or truthful (para. 113)—and judge the last one against the context and the foreseeable audience, not the deployer's intent (paras. 114–115).

That makes the test narrower than “all AI imagery” and, for advertising, sharper than many teams expect. The Commission's own examples (pp. 35–36):

  • Deep fakes: an AI-generated celebrity influencer in an advertising context; a realistic synthetic avatar of a company CEO; an AI-generated product image that could mislead people about the product's actual appearance, characteristics, or use.
  • Not deep fakes: a real product shown against an AI-generated background, as long as the ad does not mislead about the product; mice arguing about cheese in an ad; a sphinx flying over the Eiffel Tower; fictitious forests and castles in a video game.

Minor AI edits—colour correction, noise reduction, removing a passer-by, re-scaling a packshot—usually do not turn content into a deep fake, though heavier edits to journalistic images can (Guidelines, para. 116).

The Artistic Work Exception

Article 50(4) softens the deep-fake duty where the deep fake forms part of an “evidently artistic, creative, satirical, fictional or analogous work or programme”. It is not an exemption from disclosure. The deployer must still disclose, but only “in an appropriate manner that does not hamper the display or enjoyment of the work”, and still in line with Article 50(5) (Guidelines, paras. 119 and 123).

The Commission reads the categories strictly. The artistic nature must be evident to the audience, judged by format and style, the platform where the content appears, and what the audience expects. Content that is exclusively informative or commercial is excluded, and where a piece is both informative and creative, the informative character prevails (Guidelines, para. 122). A film that de-ages an actor, AI music in the style of an existing artist, and satire of a politician can qualify. A teleshopping-style ad with simulated customers, or a realistic synthetic influencer demonstrating a sponsored product, cannot (pp. 38–39). What counts as appropriate disclosure is a case-by-case call.

Our recommendation: for advertising, assume the lighter regime does not apply unless the creative treatment is unmistakably fictional or satirical. First ask whether the asset is a deep fake at all—much stylised or fantastical AI imagery is not, and needs no 50(4) label.

Article 50(4): AI-Generated Text on Matters of Public Interest (Deployer Duty)

The second subparagraph of Article 50(4) requires deployers to disclose AI-generated or manipulated text that is published to inform the public on matters of public interest. All three elements must be present: the text is published to an open audience, it communicates knowledge, opinions, or facts, and it concerns a topic such as politics, public health, consumer safety, or economic or scientific developments (Guidelines, para. 131). Ordinary advertising copy and product descriptions fall outside it, unless they make claims about health, consumer safety, or sustainability.

There is an exception where the text has undergone human review or editorial control and a person holds editorial responsibility for it. Superficial checks, a written editorial policy on its own, and automated review do not qualify, and any substantive AI edit made after sign-off voids the exception (Guidelines, paras. 133–136).

Our recommendation: if your team publishes AI-assisted thought leadership on regulated or public-interest topics, record who reviewed and approved each piece and when. That record is what makes the editorial exception usable.

Article 50(5): How and When the Information Must Be Given

Article 50(5) applies to everything in paragraphs 1 to 4. The information must be given “in a clear and distinguishable manner at the latest at the time of the first interaction or exposure”, and it must meet applicable accessibility requirements. The Commission adds three clarifications:

  • Disclosure that is easily overlooked does not count—for example, disclosure only in a manual, behind layers of menus, or in terms of use people rarely read (Guidelines, para. 142).
  • For content, the duty applies to each output and to each person exposed to it. Where people may not see a piece from the start, a label at the beginning should be complemented with later disclosure where possible (Guidelines, para. 143).
  • Article 50 adds no accessibility rules of its own, but existing EU accessibility law applies to the disclosure (Guidelines, para. 144).

Handing Assets Downstream

No paragraph of Article 50 creates a standalone legal duty to pass provenance records to the next business in the chain. What the Commission does say is that deployers in complex distribution chains should take proportionate measures to keep their 50(4) labels visible at first exposure, for example through contractual conditions with distribution partners (Guidelines, para. 12).

Our recommendation: when you deliver AI assets to a client who will publish them, include the provenance metadata and a note on which assets are deep fakes and what label they need. Handing over a folder of unlabelled PNGs does not breach Article 50 in itself, but it leaves your client unable to meet its own 50(4) duty. That is exactly the gap that surfaces in a contract dispute or a regulator's first request for evidence.

The Code of Practice and Article 50(7)

The Code of Practice on Transparency of AI-generated Content was published in final form on June 10, 2026. It covers Articles 50(2), 50(4), and 50(5), and the Commission and the AI Board have confirmed it is an adequate voluntary tool. For deployers, it includes labelling with common EU icons.

Signing is voluntary. For signatories, supervisors will focus on whether they have followed the Code. Non-signatories are expected to show compliance by other adequate means, for example with a gap analysis against the Code, and can expect more detailed information requests (Guidelines, paras. 146–148). Following the Code can also count as a mitigating factor when fines are set (para. 149).

Regulation (EU) 2026/1744, the Digital Omnibus on AI, amended Article 50(7). The Commission now assesses whether adherence to a code of practice is adequate, rather than approving a code by implementing act. If a code is not adequate, the Commission may still adopt an implementing act setting common rules for Articles 50(2), (4), and (5) (Guidelines, para. 150).

Article 50 Penalties: What Non-Compliance Actually Costs

Article 99 of the EU AI Act sets the penalties. For breaches of Article 50, the maximum fine is €15 million or 3% of total worldwide annual turnover, whichever is higher. For SMEs, including start-ups, it is whichever is lower (Guidelines, para. 152). For prohibited practices (Article 5), the ceiling is €35 million or 7% of turnover.

For an agency with €10 million in annual revenue that qualifies as an SME, the ceiling for an Article 50 breach is therefore €300,000. For a large agency group with €500 million in global turnover, it is €15 million. Authorities must weigh the nature, gravity, and duration of the breach, whether it was negligent or intentional, and how well the organisation cooperated.

Enforcement sits with the market surveillance authorities each Member State designates. The EU AI Office handles provider obligations for AI systems built on a general-purpose AI model from the same provider. Authorities can act on their own initiative or on a complaint, and anyone who believes Article 50 has been breached can lodge one (Guidelines, para. 151).

Our view: GDPR fines escalated as enforcement matured—Meta's €1.2 billion fine in 2023, Amazon's €746 million in 2021. We expect early Article 50 cases to target obvious violations, such as unlabelled deep fakes of identifiable people, rather than edge cases. Contractual exposure matters too: enterprise clients increasingly write EU AI Act warranties into master services agreements.

Beyond Europe: California SB 942

If you work with American clients or distribute content in the United States, you face a parallel obligation. California's SB 942, whose operative date AB 853 moved to August 2, 2026, requires providers of generative AI systems to embed “latent disclosures” in AI-generated content. See our SB 942 and AB 853 guide for detail.

The two laws now share an operative date but differ in important ways. SB 942 is provider-centric—it places the primary obligation on the company that builds the AI system, not the person who uses it. The EU AI Act creates obligations for both. SB 942 penalties are $5,000 per violation per day, enforced by the California Attorney General. EU penalties are a share of turnover, enforced by national market surveillance authorities.

Our view: a workflow that preserves embedded provenance and applies human-readable labels where Article 50(4) requires them covers most of what both regimes expect from creative teams. Check the provider-specific SB 942 duties separately if you build generative tools yourself.

A Five-Step Article 50 Compliance Checklist

Our recommendation. Article 50 compliance is an ongoing operational posture rather than a single project. These five steps build a foundation, and each produces a record you can show if a regulator or client asks for evidence.

Email Required

AI Governance Policy Template

A ready-to-customize policy framework that covers Article 50 obligations, three-tier content classification, disclosure templates, and audit documentation requirements.

Download free (email required)

Step 1 in Depth: The Tool Stack Audit

The tool stack audit is the most revealing exercise because it forces organizations to confront the gap between the tools they sanction and the tools employees actually use. A typical creative team uses three to seven AI tools. Sanctioned enterprise tools (Adobe Firefly, Getty Generative AI) typically produce better provenance metadata. Consumer tools (personal Midjourney subscriptions, free Stable Diffusion instances) typically produce none.

During your audit, assign each tool to one of three categories:

  • Green (C2PA support): Adobe Firefly, OpenAI DALL·E 3, and Microsoft Designer produce C2PA manifests natively. Output enters the workflow with a provenance record that can be preserved and extended.
  • Yellow (partial metadata): Some tools embed generation parameters in PNG text chunks or EXIF fields that can be translated into IPTC format. Output requires metadata enrichment at ingestion.
  • Red (no provenance): Midjourney, Stable Diffusion, and Flux produced no provenance metadata as of February 2026. Output from tools in this category needs manual documentation at ingestion.

This is a snapshot, and provider behaviour is changing: Article 50(2) now requires providers to mark their output, with a grace period to December 2, 2026 for systems already on the market. Re-check each tool's current output rather than relying on the categories above.

Step 3 in Depth: AI Disclosure Templates by Channel

The law requires a disclosure that is clear, distinguishable, and given at first exposure. It does not prescribe wording or format, so what works differs by channel. The following conventions are our recommendation, not legal requirements. To draft the notice itself, use the free AI Disclosure Generator.

  • Social media caption: “[AI-generated image]” or “Created with AI”, placed before any point where the platform truncates the caption.
  • Display advertising: an “AI” label or the Code's EU icon on the creative unit itself, in a legible size. Use more prominent placement for deep fakes of real people.
  • Editorial content: a note at the top of the piece, where readers meet it first: “Images in this article were generated using [tool name].”
  • Video content: an on-screen label at the start and, for longer pieces or feeds where viewers may join midway, again later—the Guidelines flag exactly that case (para. 143).
  • Client deliverables: a provenance cover sheet with the asset package, listing the AI tools used, which assets are deep fakes, and the labels required for distribution.
Free Tool

AI Disclosure Generator for EU AI Act Article 50

Pick your content type and distribution channel, then copy a ready-to-use AI disclosure notice. Free, no login.

Generate a disclosure

Article 50 Timeline: Key EU AI Act Dates

The EU AI Act applies in stages. These are the dates that matter for content teams.

February 2, 2025: Prohibited Practices

Article 5, which bans certain AI practices outright (such as manipulative techniques, social scoring, and untargeted scraping of facial images), has applied since February 2, 2025. The penalties for breaching it—up to €35 million or 7% of turnover—have applied since August 2, 2025.

August 2, 2025: General-Purpose AI Models

Obligations for providers of general-purpose AI models (the foundation models behind many creative tools) have applied since August 2, 2025. Models already on the market before then have until August 2, 2027. For deployers, the effect is indirect. Better provenance at the model level makes marking easier, but it does not change who carries the Article 50(4) disclosure duty.

August 2, 2026: Article 50 Applies

From this date, Article 50 applies to every in-scope system, whenever it was placed on the market (Guidelines, para. 153). Content generated or manipulated before August 2, 2026 does not have to be marked or labelled retroactively. The same goes for public-interest text generated and published before that date. But text generated before August 2 and published on or after it must be labelled (Guidelines, para. 154).

December 2, 2026: Marking Deadline for Existing Generative Systems

Regulation (EU) 2026/1744 gives providers of generative systems placed on the market before August 2, 2026 until December 2, 2026 to comply with the Article 50(2) marking obligation. Nothing else moves: the 50(1) interaction disclosure for those systems, and all deployer duties, have applied since August 2, 2026. Article 50 was not part of the Digital Omnibus deferral that pushed high-risk obligations to late 2027.

What to Do This Week

Article 50 is no longer a future compliance project; it is in force. The infrastructure decisions you make now determine whether your organization operates with confidence or keeps retrofitting compliance into workflows that were never designed for it.

The work is manageable if it starts now. Audit your tool stack, decide which of your assets are deep fakes or public-interest text, and put labels and provenance preservation in place for those first.

The complete AI Content Compliance guide covers the full regulatory landscape, including California SB 942, IPTC 2025.1 metadata standards, and C2PA technical implementation. The governance policy template gives you a ready-to-customize framework with disclosure templates, audit log formats, and training outlines for the Article 50 obligations that apply to content teams.

Primary Sources

Key Takeaways

  • Article 50 binds both providers and deployers. Anyone using AI professionally—agencies, freelancers, in-house teams—is a deployer; the personal non-professional exemption is narrow.
  • Providers carry 50(1) (tell people they are talking to AI) and 50(2) (mark synthetic output machine-readably). Deployers carry 50(3) (emotion recognition and biometric categorisation) and 50(4) (label deep fakes and public-interest text). 50(5) sets how and when every disclosure is given: clearly, accessibly, and at first exposure.
  • Not every AI image is a deep fake. The duty to label depends on realistic resemblance and false appearance of authenticity for the foreseeable audience. Misleading AI product imagery and synthetic spokespeople in ads usually qualify.
  • The artistic-work regime in 50(4) lightens how you disclose; it does not remove the duty, and it is read strictly for commercial content.
  • Article 50 has applied since August 2, 2026. Only 50(2) marking for generative systems already on the market has a grace period, to December 2, 2026, under Regulation (EU) 2026/1744. Content made before August 2 does not need retroactive labels.
  • The final Code of Practice (June 10, 2026) is the recognised way to demonstrate 50(2), 50(4), and 50(5) compliance. Non-signatories should expect to show a gap analysis against it.
  • Fines reach €15 million or 3% of worldwide turnover, whichever is higher—or whichever is lower for SMEs.

Keep Your Article 50 Evidence Intact

Numonic preserves C2PA provenance and IPTC 2025.1 AI fields through ingest and export, so the evidence behind your Article 50 disclosures survives every handoff.

Frequently Asked Questions

Quick answers about EU AI Act Article 50.

Prove compliance without the paperwork

Numonic tracks model names, input prompts and editing history automatically, so every Article 50 disclosure is backed by a searchable, timestamped record of what was made and how.